Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2020-9423EPSS 5%
LogicalDoc before 8.3.3 could allow an attacker to upload arbitrary files, leading to command execution or retrieval of data from the database. Logic…
Logicaldoc
8.3.3+
HIGH 7.2
CVE-2019-11074
A Write to Arbitrary Location in Disk vulnerability exists in PRTG Network Monitor 19.1.49 and below that allows attackers to place files in arbitrar…
Prtg Network Monitor
after 19.1.49
MEDIUM 6.5
CVE-2020-9472
Umbraco CMS 8.5.3 allows an authenticated file upload (and consequently Remote Code Execution) via the Install Package functionality.
Umbraco Cms
No fix yet
HIGH 8.8
CVE-2020-9471
Umbraco Cloud 8.5.3 allows an authenticated file upload (and consequently Remote Code Execution) via the Install Packages functionality.
Umbraco Cms
No fix yet
HIGH 7.2
CVE-2020-5844EPSS 30%
index.php?sec=godmode/extensions&sec2=extensions/files_repo in Pandora FMS v7.0 NG allows authenticated administrators to upload malicious PHP script…
Pandora Fms
No fix yet
HIGH 8.8
CVE-2020-10557
An issue was discovered in AContent through 1.4. It allows the user to run commands on the server with a low-privileged account. The upload section i…
Acontent
after 1.4
HIGH 7.2
CVE-2020-10562
An issue was discovered in DEVOME GRR before 3.4.1c. admin_edit_room.php mishandles file uploads.
Grr
3.4.1c+
HIGH 7.2
CVE-2020-10386EPSS 12%
admin/imagepaster/image-upload.php in Chadha PHPKB Standard Multi-Language 9 allows remote attackers to achieve Code Execution by uploading a .php fi…
Phpkb
No fix yet
HIGH 8.8
CVE-2015-7339
JCE Joomla Component 2.5.0 to 2.5.2 allows arbitrary file upload via a .php file extension for an image file to the /com_jce/editor/libraries/classes…
Jce
after 2.5.2
HIGH 8.8
CVE-2015-7341
JNews Joomla Component before 8.5.0 allows arbitrary File Upload via Subscribers or Templates, as demonstrated by the .php5 extension.
Jnews
8.5.0+
CRITICAL 9.8
CVE-2016-6918
Lexmark Markvision Enterprise (MVE) before 2.4.1 allows remote attackers to execute arbitrary commands by uploading files. (
Markvision Enterprise
2.4.1+
HIGH 8.8
CVE-2020-5256
BookStack before version 0.25.5 has a vulnerability where a user could upload PHP files through image upload functions, which would allow them to exe…
Bookstack
0.25.3+
CRITICAL 9.8
CVE-2020-10224EPSS 5%
An unauthenticated file upload vulnerability has been identified in admin_add.php in PHPGurukul Online Book Store 1.0. The vulnerability could be exp…
Online Book Store
No fix yet
CRITICAL 9.8
CVE-2020-10225
An unauthenticated file upload vulnerability has been identified in admin/gallery.php in PHPGurukul Job Portal 1.0. The vulnerability could be exploi…
Job Portal
No fix yet
CRITICAL 9.8
CVE-2020-9380
IPTV Smarters WEB TV PLAYER through 2020-02-22 allows attackers to execute OS commands by uploading a script.
Web Tv Player
after 2020-02-22
HIGH 8.8
CVE-2018-19798
Fleetco Fleet Maintenance Management (FMM) 1.2 and earlier allows uploading an arbitrary ".php" file with the application/x-php Content-Type to the a…
Fleet Maintenance Management
after 1.2
HIGH 7.2
CVE-2020-8500
In Artica Pandora FMS 7.42, Web Admin users can execute arbitrary code by uploading a .php file via the Updater or Extension component. NOTE: The ven…
Pandora Fms
No fix yet
HIGH 8.8
CVE-2018-17058
An issue was discovered in JABA XPress Online Shop through 2018-09-14. It contains an arbitrary file upload vulnerability in the picture-upload featu…
Jaba Xpress
after 2018-09-14
CRITICAL 9.8
CVE-2016-11020
Kunena before 5.0.4 does not restrict avatar file extensions to gif, jpeg, jpg, and png. This can lead to XSS and remote code execution.
Kunena
5.0.4+
MEDIUM 6.5
CVE-2020-5188
DNN (formerly DotNetNuke) through 9.4.4 has Insecure Permissions.
Dotnetnuke
after 9.4.4
MEDIUM 5.5
CVE-2020-9320
Avira AV Engine before 8.3.54.138 allows virus-detection bypass via a crafted ISO archive. This affects versions before 8.3.54.138 of Antivirus for E…
Anti Malware Sdk
8.3.54.138+
HIGH 8.8
CVE-2015-0258
Multiple incomplete blacklist vulnerabilities in the avatar upload functionality in manageuser.php in Collabtive before 2.1 allow remote authenticate…
Debian Linux
2.1+
CRITICAL 9.8
CVE-2011-4908EPSS 56%
TinyBrowser plugin for Joomla! before 1.5.13 allows arbitrary file upload via upload.php.
Tinybrowser
1.5.13+
CRITICAL 9.8
CVE-2011-4906EPSS 10%
Tiny browser in TinyMCE 3.0 editor in Joomla! before 1.5.13 allows file upload and arbitrary PHP code execution.
Tinybrowser
1.5.13+
CRITICAL 9.8
CVE-2013-2057
YaBB through 2.5.2: 'guestlanguage' Cookie Parameter Local File Include Vulnerability
Yabb
after 2.5.2
CRITICAL 9.8
CVE-2013-3684EPSS 19%
NextGEN Gallery plugin before 1.9.13 for WordPress: ngggallery.php file upload
Nextgen Gallery
1.9.13+
CRITICAL 9.8
CVE-2013-0803EPSS 75%
A PHP File Upload Vulnerability exists in PolarBear CMS 2.5 via upload.php, which could let a malicious user execute arbitrary code.
Polarbear Cms
No fix yet
CRITICAL 9.8
CVE-2019-20451EPSS 8%
The HTTP API in Prismview System 9 11.10.17.00 and Prismview Player 11 13.09.1100 allows remote code execution by uploading RebootSystem.lnk and requ…
Prismview Player 11
No fix yet
CRITICAL 9.8
CVE-2014-8739EPSS 92%
Unrestricted file upload vulnerability in server/php/UploadHandler.php in the jQuery File Upload Plugin 6.4.4 for jQuery, as used in the Creative Sol…
Creative Contact Form
1.0.0 / 2.0.1+
HIGH 8.8
CVE-2013-3591EPSS 43%
vTiger CRM 5.3 and 5.4: 'files' Upload Folder Arbitrary PHP Code Execution Vulnerability
Vtiger Crm
No fix yet